The old Ubuntu 10.04 LTS was also affected

Feb 5, 2015 12:37 GMT  ·  By

Canonical has published details about a Django regression in Ubuntu 12.04 LTS and Ubuntu 10.04 LTS operating systems, which has been identified and fixed.

Ubuntu devs pushed an update a while ago for a Django exploit, but it turns out that they have also pushed a regression. This current patch takes care of that problem. Users have been advised to upgrade their systems as soon as possible.

According to the security notice, "USN-2469-1 fixed vulnerabilities in Django. The security fix for CVE-2015-0221 introduced a regression on Ubuntu 10.04 LTS and Ubuntu 12.04 LTS when serving static content through GZipMiddleware. This update fixes the problem."

Among the problems corrected by the initial update was one discovered by Jedediah Smith that said Django incorrectly handled underscores in WSGI headers. A remote attacker could possibly use this issue to spoof headers.

The issue can be fixed if you upgrade your system(s) to the python-django specific to each distribution. To apply the patch, you can simply run the Update Manager application

In general, a standard system update will make all the necessary changes but a reboot of the system is not required. If you have problems updating the system, for whatever reason, Canonical provides a wiki with some instructions.